x86 rand() Calling Convention and Return Value
In x86 assembly, the C standard library function rand() is called like any other function:
call _rand
Signature and behavior
int rand(void);
- Takes no arguments.
- Returns a pseudo-random signed
intineax. - Return value range: 0 to
RAND_MAX.
What is RAND_MAX?
RAND_MAX is implementation-defined. The C standard only requires it to be at least 32767 (0x7FFF). On Windows with MSVC it is exactly 0x7FFF, so rand() returns values from 0 to 32767.
Common pattern: using only the low byte
Reverse-engineered code often uses only al after calling rand():
call _rand
mov bh, al ; bh = random byte (0..255)
cmp bh, 64h
jb short again ; reject if below 100
Because RAND_MAX = 0x7FFF, the low byte al can take any value 0x00–0xFF, but the distribution across those 256 values is not perfectly uniform. The high byte of rand()'s return will never exceed 0x7F.
Related concepts
- x86 Calling Conventions — how arguments and return values are passed
- Endianness — byte ordering when storing multi-byte values
- x86 Flags and Conditional Jumps — how
cmp/jb/jzetc. work